Skip to content

Security

Security is a system of boundaries, evidence and failure modes.

The platform is designed to minimize privilege, preserve operational evidence and make configuration-dependent controls explicit rather than silently pretending they exist.

Identity & access

Enterprise roles, tenant scope, SSO control plane, verified domains and lifecycle controls.

Audit integrity

AUD-2.0 records append-only compliance events with payload, previous and event hashes, then verifies the chain periodically.

Secrets & credentials

API keys are stored as hashes; runtime secrets are kept outside readable business entities.

Data boundaries

Organization, workspace and department identifiers define scope across sensitive entities and backend functions.

API governance

Scopes, entitlement enforcement, rate limiting, idempotency and outbound webhook protections constrain integrations.

Operational evidence

Readiness, pilot, observability and rollback controls create evidence around production operation, not just feature availability.

What the platform can state today

Technical controls implemented in the product can be inspected in the Trust Center and documentation. Those controls do not automatically create an organizational certification, legal compliance opinion or contractual availability commitment.

What remains organization-dependent

External IdP configuration, SCIM secrets, webhook signing secret, HMAC audit secret, legal privacy documents, subprocessors, RPO/RTO and contractual SLA require separate configuration, governance or approval.